FEDERALItem 8.01 · voluntaryMalwareRansomwareStolen CredentialsData ExfiltratedCustomer Data InvolvedTargetedPIICREDENTIALSIPLowActive
LUMEN TECHNOLOGIES, INC.
bd_638aa98358421f0f · schema v1 · pii pii-v1
Full breach record for LUMEN TECHNOLOGIES, INC. →Lumen Technologies disclosed two cybersecurity incidents on March 27, 2023. A malicious intruder inserted ransomware into servers supporting a segmented hosting service, degrading operations for a small number of enterprise customers. A separate sophisticated intruder accessed internal IT systems, installed malware, and extracted a limited amount of data. Lumen engaged forensic firms, notified law enforcement and customers, and is assessing the full impact.
SEC clockMateriality determined Mar 27, 2023 → Filed Mar 27, 20230d ✓ SEC 4-day OK7 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/18926/000119312523079847/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 27, 2023
- Raw hash
- 03ea101cd720c23cc6ef39998a4020c19f18e00173a2da9a64de21872ce47d45
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- LUMEN TECHNOLOGIES, INC.norm: lumen technologies
- SEC CIK
- 0000018926
Victim entity
- Name
- LUMEN TECHNOLOGIES, INC.norm: lumen technologies
- SEC CIK
- 0000018926
Incident
- Discovered
- Mar 20, 2023
- Materiality determined
- Mar 27, 2023
- Notification sent
- Mar 27, 2023
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALSIP
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified regulatory authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Mar 27, 2023→ Filed: Mar 27, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.